IP Library › Granted Patent US 11,824,995
Granted Patent B2
US 11,824,995 · App. 17/894,802 · Granted Nov 21, 2023

Bridging digital identity validation and verification with the FIDO authentication framework

Inventors: Michael Queralt (White Plains, NY); Daniel R. Sabia (Glastonbury, CT)
Assignee: Queralt Inc.
H04L9/3263G06F21/64H04L63/0853H04L63/0884H04L9/3247H04L9/3297H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,824,995
App. No.
17/894,802
Granted
Nov 21, 2023
Kind
B2
Abstract

A system and method for integrating FIDO authentication systems and user verification systems. The system is provided in one configuration as a mobile app that allows access to highly sensitive information via a mobile device while simultaneously ensuring a highly secured environment authenticating both the mobile device and the user via a highly reliable authentication process.

Claims (27)

1. A system for peer-to-peer authentication of a mobile device with a server via a network connection based on information relating to a user and the mobile device, the system comprising:

the mobile device transmitting an authentication request to the server via a network connection; said server transmitting data relating to the authentication request to a Fast Identity Online (FIDO) authentication system;

the mobile device receiving an authentication communication from the FIDO authentication system;

the mobile device retrieving information related to the user and associated with a digital document generated by a verification system;

wherein the retrieved information is selected from the group consisting of: a field from the digital document, a digital signature, a user name, an email address, an expiration date, data relating to rights and uses associated with the digital document, an identity of the verification system, an algorithm identifier relating to a signature for the digital document and combinations thereof;

the mobile device validating the integrity of the digital document;

the mobile device inserting at least some of the retrieved information into an authentication message; and

the mobile device transmitting the authentication message to the FIDO authentication system.

2. The system according to claim 1 , wherein the verification system comprises Public Key Infrastructure (PKI) or Decentralized Identity (DID).

3. The system according to claim 2 , wherein when the user verification system is selected to be PKI the digital document is a x.509 certificate.

4. The system according to claim 2 , wherein when the verification system is selected to be DID, the digital document comprises a DID document generated by a Decentralized Identity system.

5. The system according to claim 2 , wherein,

the mobile device transmits the retrieved information to the user verification system; and

the user verification system transmits an attestation to the mobile device that the retrieved information is verified.

6. The system according to claim 4 , wherein

the verification of the retrieved information is done via a service end point to a verifiable data registry; and

the verifiable data registry comprises a distributed ledger, a decentralized file system, a database, a peer-to-peer network, or combinations thereof.

7. The system according to claim 1 , wherein the authentication message comprises information relating to the digital document, the mobile device, or combinations thereof.

8. The system according to claim 1 , wherein the FIDO authentication system uses UAF protocol, U2F protocol, or FIDO2 protocol.

9. The system according to claim 8 , wherein the FIDO2 protocol comprises Client-to-Authenticator Protocols including CTAP1 or CTAP2.

10. The system according to claim 1 , wherein validation of the integrity of the digital document comprises checking a public key, a validity date, a verifiable time stamp, a certificate signature algorithm, or a digital signature.

11. The system according to claim 1 , wherein the transmitting of the authentication message is contingent upon the validation of the integrity of the digital document.

12. The system according to claim 1 , wherein validation of the integrity of the digital document occurs by checking that the digital document or data contained in the digital document has not been modified.

13. The system according to claim 1 , wherein the authentication request comprises a registration request for registering the mobile device with the server and includes information from the digital document.

14. The system according to claim 13 , wherein data transmitted from the server to the FIDO authentication system includes data relating to the registration request based on a public-private key pair; and

wherein said authentication message comprises a registration message that includes information about the user retrieved from the digital document and is based on the public-private key pair and at least some of the user information is stored and accessible by the server.

15. The system according to claim 1 , wherein the server stores at least some of the information related to the user on a storage accessible by the server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2022
From: QUERALT, MICHAEL; SABIA, DANIEL R.
To: QUERALT, INC.
Reel/Frame 061841/0390 →
Continuity (5)
Continuation 17122631 · Dec 15, 2020
Continuation In Part 15819605 · Nov 21, 2017
Continuation In Part 15703138 · Sep 13, 2017
Provisional Application 62393893 · Sep 13, 2016
Related Publication 20220407721A1 · Dec 22, 2022